GPU VulnDB

Database/Firmware, BMC & network fabric

Linux RDMA/srpt: failed multi-buffer descriptor setup leaves stale counters and a dangling rw_ctxs pointer

CVSS 9.8CVE-2026-100075Firmware, BMC & network fabriccurated

Impact

When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys the RDMA contexts but leaves n_rw_ctx and n_rdma set and rw_ctxs dangling. Later send-queue credit accounting in srpt_queue_response() or srpt_write_pending() then subtracts the wrong number of credits, and a freed pointer remains reachable. This only matters on nodes that export SRP targets over InfiniBand/RoCE - a storage or fabric-attached node in a GPU cluster, not a plain compute node. Reaching it requires a client that can open an SRP session to the target and drive descriptor allocation to failure; NVD's 9.8 network score is the automated kernel-CNA default and overstates how exposed a typical fleet is, since the SRP target fabric is usually a trusted storage network.

Who can reach it

A host that can establish an SRP session with the target over the RDMA fabric. Only nodes running the srpt target module are affected; if ib_srpt is not loaded, there is no exposure.

What to do

Take the stable-kernel fix on affected nodes (five stable branches carry it) and reboot, or unload/reload ib_srpt if your kernel packaging allows it - in practice the SRP target has to be taken out of service either way. No vendor-supplied mitigation short of not running the SRP target.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.